{"id":"72585890-584d-4851-8bb7-c65d041ae595","entityType":"agent","slug":"clawhub-sdk-team-alibabacloud-alinux-sysom-inspection","name":"alibabacloud-alinux-sysom-inspection","canonicalUrl":"https://www.xpersona.co/agent/clawhub-sdk-team-alibabacloud-alinux-sysom-inspection","canonicalPath":"/agent/clawhub-sdk-team-alibabacloud-alinux-sysom-inspection","generatedAt":"2026-10-11T03:56:57.099Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"editorial-content","verified":true,"confidence":"high","updatedAt":"2026-10-11T00:31:43.677Z","emptyReason":null},"description":"Inspect ECS instance health, detect anomalies in memory, disk, CPU, load, and resource leaks, and automatically trigger deep diagnosis when critical memory issues are detected. Suitable for routine inspections, troubleshooting, and risk warning scenarios. Trigger keywords: SysOM, inspection, instance diagnosis, memory_usage_rate, memory usage. Skill: alibabacloud-alinux-sysom-inspection Owner: sdk-team Summary: Inspect ECS instance health, detect anomalies in memory, disk, CPU, load, and resource leaks, and automatically trigger deep diagnosis when critical memory issues are detected. Suitable for routine inspections, troubleshooting, and risk warning scenarios. Trigger keywords: SysOM, inspection, instance diagnosis, memory_usage_rate, memory usage. Tags:","descriptionLabel":"Technical summary","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 1.2K downloads reported by the source. Last updated 10/11/2026.","installCommand":"clawhub skill install s173swjet2yrebzqrp6hjkvmy583mxef:alibabacloud-alinux-sysom-inspection","sourceUrl":"https://clawhub.ai/sdk-team/alibabacloud-alinux-sysom-inspection","homepage":"https://clawhub.ai/sdk-team/skills/alibabacloud-alinux-sysom-inspection","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/sdk-team/alibabacloud-alinux-sysom-inspection","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/sdk-team/skills/alibabacloud-alinux-sysom-inspection","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":62,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"Inspect ECS instance health, detect anomalies in memory, disk, CPU, load, and resource leaks, and automatically trigger deep diagnosis when critical memory issu"},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-11T00:31:43.677Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-11T00:31:43.677Z","emptyReason":null},"stars":null,"forks":null,"downloads":1218,"packageName":null,"latestVersion":"0.0.5","tractionLabel":"1.2K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-11T00:31:43.613Z","emptyReason":null},"lastUpdatedAt":"2026-10-11T00:31:43.677Z","lastCrawledAt":"2026-10-11T00:31:43.613Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-12T00:31:43.613Z","lastVerifiedAt":null,"highlights":[{"version":"0.0.5","createdAt":"2026-09-08T03:49:35.123Z","changelog":"- Added `references/manifest.json` for improved metadata management. - Clarified in documentation that, when replaying a report with `--report-id`, the original `--region` and `--scope-type` (or `--instance`) must match the original inspection for the replay to succeed. - Updated invocation instructions and replay command examples for accuracy and completeness. - Removed outdated `skill-card.md` file. - Minor documentation updates and corrections in `SKILL.md` and references.","fileCount":17,"zipByteSize":27684},{"version":"0.0.4","createdAt":"2026-08-20T06:51:33.370Z","changelog":"alibabacloud-alinux-sysom-inspection 0.2.0 introduces enhanced CLI workflows and report handling. - Switched to `sysom-osops` CLI for all inspection tasks, replacing direct script/API usage. - Added support for intent-driven inspections via `--query` and new batch/region-wide modes. - Integrated automatic root-cause diagnosis on Top-3 anomalies and LLM-generated summary reports. - Improved error handling with clear guidance for permissions, throttling, argument errors, and empty regions. - Provides new quickstart commands and detailed invocation examples in documentation. - Deprecated legacy local Python CLI except as a fallback.","fileCount":16,"zipByteSize":24447},{"version":"0.0.3","createdAt":"2026-07-06T12:05:47.398Z","changelog":"alibabacloud-alinux-sysom-inspection v0.0.3 - Added sample inspection report template for reference. - Improved logic in main CLI and inspection command scripts. - Updated authentication and OpenAPI utility modules. - Cleaned up project documentation; removed outdated skill card. - General maintenance and minor fixes across scripts and docs.","fileCount":16,"zipByteSize":23236},{"version":"0.0.2","createdAt":"2026-06-17T16:45:26.236Z","changelog":"alibabacloud-alinux-sysom-inspection 0.0.2 - Enhanced inspection CLI to support unified session-id (SKILL_SESSION_ID) injection and propagation for all API calls, enabling better observability and traceability. - Updated user agent format for all SDK requests to include skill name and session ID. - Added new options for instance filtering and metric source selection (e.g., --managed-type, --metric-source). - Improved interactive behavior when SysOM is not activated or an instance ID is not provided. - Documentation updated for English localization, expanded quick start, and new option descriptions. - Removed obsolete skill-card.md.","fileCount":15,"zipByteSize":19852},{"version":"0.0.1","createdAt":"2026-05-20T09:55:46.062Z","changelog":"Version 0.1.0 introduces the initial release of the skill. - Provides automated system health inspection for Alibaba Cloud ECS instances, identifying issues with memory, disk, CPU, load, and resource leaks. - Integrates interactive CLI for diagnostics, role validation, and SysOM activation/installation when necessary. - Automatically triggers deeper memory diagnostics (memgraph) if inspection reports memory usage anomalies. - Supports full project inspection, customizable inspection items, and disables memory diagnostics via CLI flags. - Offers robust error handling and logging for unavailable APIs and inspection/report retrieval.","fileCount":15,"zipByteSize":17055}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s173swjet2yrebzqrp6hjkvmy583mxef:alibabacloud-alinux-sysom-inspection","setupComplexity":"low","setupSteps":["Setup complexity is LOW. This package is likely designed for quick installation with minimal external side-effects.","Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-sdk-team-alibabacloud-alinux-sysom-inspection/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-sdk-team-alibabacloud-alinux-sysom-inspection/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-sdk-team-alibabacloud-alinux-sysom-inspection/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-sdk-team-alibabacloud-alinux-sysom-inspection/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-sdk-team-alibabacloud-alinux-sysom-inspection/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-sdk-team-alibabacloud-alinux-sysom-inspection/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-11T03:56:57.098Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-sdk-team-alibabacloud-alinux-sysom-inspection/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-sdk-team-alibabacloud-alinux-sysom-inspection/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-sdk-team-alibabacloud-alinux-sysom-inspection/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-sdk-team-alibabacloud-alinux-sysom-inspection/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"high","updatedAt":"2026-10-11T00:31:43.677Z","emptyReason":null},"readme":"Skill: alibabacloud-alinux-sysom-inspection\n\nOwner: sdk-team\n\nSummary: Inspect ECS instance health, detect anomalies in memory, disk, CPU, load, and resource leaks, and automatically trigger deep diagnosis when critical memory issues are detected. Suitable for routine inspections, troubleshooting, and risk warning scenarios. Trigger keywords: SysOM, inspection, instance diagnosis, memory_usage_rate, memory usage.\n\nTags: latest:0.0.5\n\nVersion history:\n\nv0.0.5 | 2026-09-08T03:49:35.123Z | auto\n\n- Added `references/manifest.json` for improved metadata management.\n- Clarified in documentation that, when replaying a report with `--report-id`, the original `--region` and `--scope-type` (or `--instance`) must match the original inspection for the replay to succeed.\n- Updated invocation instructions and replay command examples for accuracy and completeness.\n- Removed outdated `skill-card.md` file.\n- Minor documentation updates and corrections in `SKILL.md` and references.\n\nv0.0.4 | 2026-08-20T06:51:33.370Z | auto\n\nalibabacloud-alinux-sysom-inspection 0.2.0 introduces enhanced CLI workflows and report handling.\n\n- Switched to `sysom-osops` CLI for all inspection tasks, replacing direct script/API usage.\n- Added support for intent-driven inspections via `--query` and new batch/region-wide modes.\n- Integrated automatic root-cause diagnosis on Top-3 anomalies and LLM-generated summary reports.\n- Improved error handling with clear guidance for permissions, throttling, argument errors, and empty regions.\n- Provides new quickstart commands and detailed invocation examples in documentation.\n- Deprecated legacy local Python CLI except as a fallback.\n\nv0.0.3 | 2026-07-06T12:05:47.398Z | auto\n\nalibabacloud-alinux-sysom-inspection v0.0.3\n\n- Added sample inspection report template for reference.\n- Improved logic in main CLI and inspection command scripts.\n- Updated authentication and OpenAPI utility modules.\n- Cleaned up project documentation; removed outdated skill card.\n- General maintenance and minor fixes across scripts and docs.\n\nv0.0.2 | 2026-06-17T16:45:26.236Z | auto\n\nalibabacloud-alinux-sysom-inspection 0.0.2\n\n- Enhanced inspection CLI to support unified session-id (SKILL_SESSION_ID) injection and propagation for all API calls, enabling better observability and traceability.\n- Updated user agent format for all SDK requests to include skill name and session ID.\n- Added new options for instance filtering and metric source selection (e.g., --managed-type, --metric-source).\n- Improved interactive behavior when SysOM is not activated or an instance ID is not provided.\n- Documentation updated for English localization, expanded quick start, and new option descriptions.\n- Removed obsolete skill-card.md.\n\nv0.0.1 | 2026-05-20T09:55:46.062Z | auto\n\nVersion 0.1.0 introduces the initial release of the skill.\n\n- Provides automated system health inspection for Alibaba Cloud ECS instances, identifying issues with memory, disk, CPU, load, and resource leaks.\n- Integrates interactive CLI for diagnostics, role validation, and SysOM activation/installation when necessary.\n- Automatically triggers deeper memory diagnostics (memgraph) if inspection reports memory usage anomalies.\n- Supports full project inspection, customizable inspection items, and disables memory diagnostics via CLI flags.\n- Offers robust error handling and logging for unavailable APIs and inspection/report retrieval.\n\nArchive index:\n\nArchive v0.0.5: 17 files, 27684 bytes\n\nFiles: references/manifest.json (19b), references/ram-policies.md (1811b), references/report-template.md (744b), scripts/init.sh (310b), scripts/osops.sh (618b), scripts/pyproject.toml (409b), scripts/requirements.txt (93b), scripts/sysom_cli/__init__.py (24b), scripts/sysom_cli/__main__.py (6569b), scripts/sysom_cli/inspection/__init__.py (24b), scripts/sysom_cli/inspection/command.py (57170b), scripts/sysom_cli/lib/__init__.py (24b), scripts/sysom_cli/lib/auth.py (7067b), scripts/sysom_cli/lib/openapi.py (7204b), skill-card.md (2260b), SKILL.md (8850b), _meta.json (155b)\n\nFile v0.0.5:SKILL.md\n\n---\nname: alibabacloud-alinux-sysom-inspection\nversion: 0.2.0\ndescription: >\n  Inspect ECS instance health, detect anomalies in memory, disk, CPU, load,\n  and resource leaks, and automatically trigger deep diagnosis when critical\n  memory issues are detected. Suitable for routine inspections, troubleshooting,\n  and risk warning scenarios. Trigger keywords: SysOM, inspection, instance\n  diagnosis, memory_usage_rate, memory usage.\nlayer: application\ncategory: os-ops\nlifecycle: operations\ntags:\n  - sysom\n  - inspection\n  - ecs\n  - memory\n  - diagnosis\nstatus: beta\n---\n\n# SysOM Inspection (`sysom-inspection`)\n\nInspections are launched with the `sysom-osops` CLI command\n(`sysom-osops inspection ecs ...`). Always go through the CLI instead of calling\nthe inspection OpenAPI directly.\n\n## CLI Setup\n\nCheck whether the CLI is available:\n\n```bash\ncommand -v sysom-osops\n```\n\nIf it is missing, install it:\n\n```bash\ncurl -fsSL --connect-timeout 1000 https://sysom-prd-cn-hangzhou.oss-cn-hangzhou.aliyuncs.com/sysom_prd/skill_cli/install.sh | sudo bash\n```\n\nThen verify only the binary:\n\n```bash\ncommand -v sysom-osops\n```\n\nIf the CLI is installed but has no `inspection` subcommand yet, run\n`sysom-osops update` first, then retry.\n\nIf a command fails due to missing RAM permissions, follow\n`references/ram-policies.md` to attach the minimum permission policy.\n\n## Quick Start\n\n```bash\n# Focused inspection by intent (--query)\n# Run only CPU/load related items (keyword mapping)\nsysom-osops inspection ecs --region cn-shenzhen --instance i-xxxxxxxx --query \"cpu related inspection\"\n\n# Combined intent: memory and disk\nsysom-osops inspection ecs --region cn-shenzhen --instance i-xxxxxxxx --query \"memory and disk\"\n\n# Natural-language sentence: intent is extracted automatically, matching packet-loss items\nsysom-osops inspection ecs --region cn-shenzhen --instance i-xxxxxxxx --query \"check whether this machine has network packet loss\"\n\n# If the query matches no items, it falls back to a full inspection automatically\n\n# Batch inspection (--scope-type batch, auto diagnosis supported)\n# Inspect all specified instances -> auto root-cause diagnosis on the Top-3 most severe\n# anomalous instances -> LLM summary (the rest get copy-ready deep-dive commands in the report)\nsysom-osops inspection ecs --region cn-shenzhen --scope-type batch --instances i-aaa,i-bbb,i-ccc\n\n# Region-wide inspection (--scope-type all, auto diagnosis supported)\n# Auto-discover every ECS instance in the region (limit 5000) -> Top-3 anomalies auto-diagnosed\n# -> LLM summary; one command for the full closed loop\nsysom-osops inspection ecs --region cn-shenzhen --scope-type all\n\n# Re-check an existing report (--report-id)\n# Returns immediately without re-running (auto-generated in inspection next_steps).\n# IMPORTANT: --region and --scope-type (or --instance) MUST match the original\n# inspection command, otherwise the replay will fail with MissingParam errors.\nsysom-osops inspection ecs --region cn-shenzhen --scope-type all --report-id inspection-82a64d9d-11c5-45b2-a81c-27fc754891e8\n```\n\n## Invocation Modes\n\n- **Focused inspection:** `--query \"<intent>\"` maps keywords or extracted intent to concrete\n  items (CPU/load keyword mapping, combined intents such as memory + disk, natural-language\n  sentences such as network packet-loss checks). A query matching no items falls back to a\n  full inspection automatically.\n- **Batch:** `--scope-type batch --instances i-aaa,i-bbb,...` inspects all specified instances,\n  auto-diagnoses the Top-3 most severe anomalous ones, and lists copy-ready deep-dive commands\n  for the rest in the report.\n- **Region-wide:** `--scope-type all` auto-discovers every ECS instance in the region\n  (limit 5000), then applies the same Top-3 auto-diagnosis and LLM summarization in one command.\n- **Report replay:** `--region <region> --scope-type <scope-type> --report-id <reportId>`\n  (or `--region <region> --instance <instanceId> --report-id <reportId>`) returns the\n  existing report immediately without re-running the inspection; inspection results emit\n  this replay command — with the original `--region` and `--scope-type`/`--instance` —\n  in `next_steps` automatically.\n\n## Observability\n\n- **UA template (required for all SDK requests):**\n  - `AlibabaCloud-Agent-Skills/{SKILL_NAME}/{session-id}`\n  - Runtime resolved form in this skill: `AlibabaCloud-Agent-Skills/alibabacloud-alinux-sysom-inspection/<SKILL_SESSION_ID>`\n- **Unified session-id rule:**\n  - A single session-id is generated once per session (one CLI execution) and must be\n    reused consistently across all API calls, both CLI and SDK requests.\n  - Generation priority: external env `SKILL_SESSION_ID` (preferred) -> auto-generated\n    fallback `sid-<32-char hex>` (uuid4 hex); invalid injected values fall back to the\n    generated id.\n  - Accepted format: `[A-Za-z0-9][A-Za-z0-9._:-]{7,127}`.\n  - The resolved value is exported to process env `SKILL_SESSION_ID` so downstream calls\n    stay consistent.\n- The `sysom-osops` CLI injects the UA header automatically and follows the same unified\n  session-id rule.\n\n## Execution Flow\n\n- Before each inspection, the CLI verifies SysOM activation and permissions (`InitialSysom`,\n  `source=skill_hub`); activation and installation prompts are handled by the CLI itself.\n- Every new inspection calls ROA API `POST /api/v1/inspection/createInstanceInspection` with\n  `source=skill_hub`; selected items come from `--query` keyword/intent mapping, and a query\n  matching no items falls back to a full inspection.\n- Each mode runs a full closed loop: inspect (metrics + logs) -> automatic root-cause diagnosis\n  on detected anomalies -> LLM-summarized Chinese report.\n- Automatic root-cause diagnosis is triggered via `InvokeDiagnosis` (injecting\n  `__sysom_diagnosis_source=skill_hub` into `params`) and polled via `GetDiagnosisResult`\n  until `success` / `fail` / timeout.\n- Batch (`--scope-type batch --instances ...`) inspects every specified instance; region-wide\n  (`--scope-type all`) auto-discovers all ECS instances in the region (limit 5000). Both\n  automatically diagnose the Top-3 most severe anomalous instances and include copy-ready\n  deep-dive commands for the remaining ones in the report.\n- Report lookup uses ROA API `GET /api/v1/inspection/getInspectionReport`; the CLI polls until\n  the report succeeds or times out.\n- `--region <region> --scope-type <scope-type> --report-id <reportId>` (or with\n  `--instance` instead of `--scope-type`) skips task creation and directly fetches the\n  existing report; inspection results emit this replay command in `next_steps`\n  automatically, including the original `--region` and `--scope-type`/`--instance`.\n- Local threshold/event-rule configuration is not used; anomaly decisions come from the\n  server-side inspection report.\n\n## Error Handling\n\nWhen a CLI invocation fails, classify the failure by the error text (`Error: <Code>: ...`)\nand handle it as follows instead of blind retries:\n\n- **Permission (`Forbidden.RAM`)**: explain that `sysom:InitialSysom` /\n  `sysom:InvokeAgentCli` is missing and point the user to `references/ram-policies.md`\n  for the minimum policy; do not retry.\n- **Parameter (`InvalidParameter`, invalid argument)**: identify the offending argument\n  and guide the user to verify the instance id and region; do not attribute it to the\n  service.\n- **Throttling (`Throttling`)**: tell the user the request was rate-limited and advise\n  retrying later; do not retry automatically in a loop.\n- **Internal (`InternalError`)**: report the temporary service failure honestly and\n  suggest retrying later; do not attribute it to user input.\n- **Empty region (`no ECS instances found`)**: not an error. Report that the region has\n  no ECS instances and skip the inspection; never fabricate a report.\n\n## Extensibility Notes\n\n- Inspection focus is controlled by `--query` (keyword/intent mapping to concrete items);\n  unmatched queries fall back to a full inspection.\n- Use `--scope-type batch --instances ...` for batch inspection and `--scope-type all` for the\n  whole region (limit 5000 instances); both auto-diagnose the Top-3 most severe anomalies.\n- Use `--region <region> --scope-type <scope-type> --report-id <reportId>` (or with\n  `--instance` instead of `--scope-type`) to re-check an existing report without\n  re-execution; the replay command is emitted automatically in inspection `next_steps`\n  with the original `--region` and `--scope-type`/`--instance`.\n- A local Python CLI (`./scripts/osops.sh inspection`) is kept only as a fallback for\n  environments where `sysom-osops` is unavailable.\n- Memory anomaly trigger logic of the fallback path stays implemented in\n  `scripts/sysom_cli/inspection/command.py`.\n- To add more post-inspection specialized diagnosis actions, reuse the `InvokeDiagnosis`\n  integration pattern.\n\nFile v0.0.5:_meta.json\n\n{\n  \"ownerId\": \"kn74p5w8ywv6prh40g0s82gmqh83nw54\",\n  \"slug\": \"alibabacloud-alinux-sysom-inspection\",\n  \"version\": \"0.0.5\",\n  \"publishedAt\": 1788839375123\n}\n\nFile v0.0.5:references/manifest.json\n\n{\"version\":\"0.0.5\"}\n\nFile v0.0.5:references/ram-policies.md\n\n# RAM Policies: alibabacloud-alinux-sysom-inspection\n\nThis Skill uses the sysom-osops CLI. Remote diagnosis is routed through SysOM\nOpenAPI gateway actions.\n\n## Required Permissions\n\n| API | RAM Action | Used by | Description |\n|-----|------------|---------|-------------|\n| InitialSysom | `sysom:InitialSysom` | Credential validation inside remote commands | Verify credential validity and SysOM role authorization |\n| InvokeAgentCli | `sysom:InvokeAgentCli` | All remote diagnosis commands | Gateway action for catalog queries, diagnosis execution, and task polling |\n| CreateServiceLinkedRole | `ram:CreateServiceLinkedRole` | First-time SysOM service activation | Create the SysOM service-linked role (SLR). Only needed on first activation. |\n\n## Minimum Permission Policy\n\n```json\n{\n  \"Version\": \"1\",\n  \"Statement\": [\n    {\n      \"Effect\": \"Allow\",\n      \"Action\": [\n        \"sysom:InitialSysom\",\n        \"sysom:InvokeAgentCli\"\n      ],\n      \"Resource\": \"*\"\n    },\n    {\n      \"Effect\": \"Allow\",\n      \"Action\": \"ram:CreateServiceLinkedRole\",\n      \"Resource\": \"*\",\n      \"Condition\": {\n        \"StringEquals\": {\n          \"ram:ServiceName\": \"sysom.aliyuncs.com\"\n        }\n      }\n    }\n  ]\n}\n```\n\n## Notes\n\n- `sysom-osops memory classify` runs locally and does not require cloud\n  permissions.\n- Remote commands across memory, IO, network, load, and Java memory require the\n  permissions above.\n- `ram:CreateServiceLinkedRole` is only required when activating SysOM for the\n  first time. Once the service-linked role exists, subsequent calls succeed\n  without this permission.\n- Avoid broader wildcard permissions when a custom least-privilege policy can be\n  attached to the RAM user or ECS RAM Role.\n- Do not paste AK/SK values into the conversation. Configure credentials outside\n  the Agent session.\n\nFile v0.0.5:references/report-template.md\n\n## Inspection Overview\n- Target Instance: `{instance_id}` ({region_id})\n- Inspection Time: `{report_time}`\n- Inspection Report: `{inspection_report_id}` (Status: {inspection_report_status})\n- Inspection Result: {inspection_report_result}\n- Report File: `{report_file_name}`\n- File Path: `{report_file_path}`\n\n## Abnormal Item Details\n{abnormal_items_markdown}\n\n## Diagnosis Information\n- Diagnosis Status: {diagnosis_status}\n- Diagnosis Task: `{diagnosis_task_id}`\n- Diagnosis Conclusion: {diagnosis_report_result}\n- Root Cause: {diagnosis_root_cause}\n- Suggestion: {diagnosis_suggestion}\n\n## Key Findings\n{diagnosis_key_findings}\n\n## Application Memory Usage Ranking (TOP10)\n{diagnosis_app_mem_ranking}\n\n## Final Conclusion\n{final_conclusion}\n\nFile v0.0.5:scripts/pyproject.toml\n\n[build-system]\nrequires = [\"setuptools>=45\", \"wheel\"]\nbuild-backend = \"setuptools.build_meta\"\n\n[project]\nname = \"sysom-inspection\"\nversion = \"0.1.0\"\ndescription = \"SysOM inspection CLI\"\nrequires-python = \">=3.8\"\ndependencies = [\n    \"requests>=2.31.0\",\n    \"alibabacloud-tea-openapi>=0.4.4,<1.0.0\",\n    \"alibabacloud-tea-util>=0.3.14,<1.0.0\",\n]\n\n[project.scripts]\nsysom-inspection = \"sysom_cli.__main__:main\"\n\nFile v0.0.5:scripts/requirements.txt\n\nrequests>=2.31.0\nalibabacloud-tea-openapi>=0.4.4,<1.0.0\nalibabacloud-tea-util>=0.3.14,<1.0.0\n\nFile v0.0.5:skill-card.md\n\n## Description:\n\nInspects Alibaba Cloud ECS instance health for memory, disk, CPU, load, and resource-leak anomalies, and can trigger deeper SysOM diagnosis for critical memory issues.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[sdk-team](https://clawhub.ai/user/sdk-team)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and cloud operations engineers use this skill to inspect Alibaba Cloud ECS instances, triage health anomalies, and obtain SysOM diagnosis reports for routine operations, troubleshooting, and risk warnings.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The skill asks users to run an unverified remote installer as root.\n\nMitigation: Review the installer out of band or replace it with a pinned, verified package before installation.\n\nRisk: The inspection workflow can activate SysOM, install an agent on ECS, call cloud diagnosis APIs, and save local inspection reports.\n\nMitigation: Run with least-privilege Alibaba Cloud credentials and confirm service activation, agent installation, and local report storage are intended.\n\nRisk: Region-wide mode can inspect a broad set of ECS instances.\n\nMitigation: Use focused or batch inspection unless region-wide inspection is explicitly authorized and intended.\n\n## Reference(s):\n\n- [RAM Policies](artifact/references/ram-policies.md)\n- [Inspection Report Template](artifact/references/report-template.md)\n- [Skill Manifest](artifact/references/manifest.json)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, shell commands, configuration, guidance]\n\n**Output Format:** [CLI-readable text or JSON, with Markdown inspection reports saved to local files]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [May include inspection conclusions, diagnosis results, report file paths, replay commands, and copy-ready deep-dive commands.]\n\n## Skill Version(s):\n\n0.0.5 (source: server release metadata and references/manifest.json)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.0.4: 16 files, 24447 bytes\n\nFiles: references/ram-policies.md (1229b), references/report-template.md (744b), scripts/init.sh (310b), scripts/osops.sh (618b), scripts/pyproject.toml (396b), scripts/requirements.txt (79b), scripts/sysom_cli/__init__.py (24b), scripts/sysom_cli/__main__.py (4409b), scripts/sysom_cli/inspection/__init__.py (24b), scripts/sysom_cli/inspection/command.py (53088b), scripts/sysom_cli/lib/__init__.py (24b), scripts/sysom_cli/lib/auth.py (3784b), scripts/sysom_cli/lib/openapi.py (7204b), skill-card.md (2241b), SKILL.md (8136b), _meta.json (155b)\n\nFile v0.0.4:SKILL.md\n\n---\nname: alibabacloud-alinux-sysom-inspection\nversion: 0.2.0\ndescription: >\n  Inspect ECS instance health, detect anomalies in memory, disk, CPU, load,\n  and resource leaks, and automatically trigger deep diagnosis when critical\n  memory issues are detected. Suitable for routine inspections, troubleshooting,\n  and risk warning scenarios. Trigger keywords: SysOM, inspection, instance\n  diagnosis, memory_usage_rate, memory usage.\nlayer: application\ncategory: os-ops\nlifecycle: operations\ntags:\n  - sysom\n  - inspection\n  - ecs\n  - memory\n  - diagnosis\nstatus: beta\n---\n\n# SysOM Inspection (`sysom-inspection`)\n\nInspections are launched with the `sysom-osops` CLI command\n(`sysom-osops inspection ecs ...`). Always go through the CLI instead of calling\nthe inspection OpenAPI directly.\n\n## CLI Setup\n\nCheck whether the CLI is available:\n\n```bash\ncommand -v sysom-osops\n```\n\nIf it is missing, install it:\n\n```bash\ncurl -fsSL --connect-timeout 1000 https://sysom-prd-cn-hangzhou.oss-cn-hangzhou.aliyuncs.com/sysom_prd/skill_cli/install.sh | sudo bash\n```\n\nThen verify only the binary:\n\n```bash\ncommand -v sysom-osops\n```\n\nIf the CLI is installed but has no `inspection` subcommand yet, run\n`sysom-osops update` first, then retry.\n\nIf a command fails due to missing RAM permissions, follow\n`references/ram-policies.md` to attach the minimum permission policy.\n\n## Quick Start\n\n```bash\n# Focused inspection by intent (--query)\n# Run only CPU/load related items (keyword mapping)\nsysom-osops inspection ecs --region cn-shenzhen --instance i-xxxxxxxx --query \"cpu related inspection\"\n\n# Combined intent: memory and disk\nsysom-osops inspection ecs --region cn-shenzhen --instance i-xxxxxxxx --query \"memory and disk\"\n\n# Natural-language sentence: intent is extracted automatically, matching packet-loss items\nsysom-osops inspection ecs --region cn-shenzhen --instance i-xxxxxxxx --query \"check whether this machine has network packet loss\"\n\n# If the query matches no items, it falls back to a full inspection automatically\n\n# Batch inspection (--scope-type batch, auto diagnosis supported)\n# Inspect all specified instances -> auto root-cause diagnosis on the Top-3 most severe\n# anomalous instances -> LLM summary (the rest get copy-ready deep-dive commands in the report)\nsysom-osops inspection ecs --region cn-shenzhen --scope-type batch --instances i-aaa,i-bbb,i-ccc\n\n# Region-wide inspection (--scope-type all, auto diagnosis supported)\n# Auto-discover every ECS instance in the region (limit 5000) -> Top-3 anomalies auto-diagnosed\n# -> LLM summary; one command for the full closed loop\nsysom-osops inspection ecs --region cn-shenzhen --scope-type all\n\n# Re-check an existing report (--report-id)\n# Returns immediately without re-running (auto-generated in inspection next_steps)\nsysom-osops inspection ecs --report-id inspection-82a64d9d-11c5-45b2-a81c-27fc754891e8\n```\n\n## Invocation Modes\n\n- **Focused inspection:** `--query \"<intent>\"` maps keywords or extracted intent to concrete\n  items (CPU/load keyword mapping, combined intents such as memory + disk, natural-language\n  sentences such as network packet-loss checks). A query matching no items falls back to a\n  full inspection automatically.\n- **Batch:** `--scope-type batch --instances i-aaa,i-bbb,...` inspects all specified instances,\n  auto-diagnoses the Top-3 most severe anomalous ones, and lists copy-ready deep-dive commands\n  for the rest in the report.\n- **Region-wide:** `--scope-type all` auto-discovers every ECS instance in the region\n  (limit 5000), then applies the same Top-3 auto-diagnosis and LLM summarization in one command.\n- **Report replay:** `--report-id <reportId>` returns the existing report immediately without\n  re-running the inspection; inspection results emit this replay command in `next_steps`\n  automatically.\n\n## Observability\n\n- **UA template (required for all SDK requests):**\n  - `AlibabaCloud-Agent-Skills/{SKILL_NAME}/{session-id}`\n  - Runtime resolved form in this skill: `AlibabaCloud-Agent-Skills/alibabacloud-alinux-sysom-inspection/<SKILL_SESSION_ID>`\n- **Unified session-id rule:**\n  - A single session-id is generated once per session (one CLI execution) and must be\n    reused consistently across all API calls, both CLI and SDK requests.\n  - Generation priority: external env `SKILL_SESSION_ID` (preferred) -> auto-generated\n    fallback `sid-<32-char hex>` (uuid4 hex); invalid injected values fall back to the\n    generated id.\n  - Accepted format: `[A-Za-z0-9][A-Za-z0-9._:-]{7,127}`.\n  - The resolved value is exported to process env `SKILL_SESSION_ID` so downstream calls\n    stay consistent.\n- The `sysom-osops` CLI injects the UA header automatically and follows the same unified\n  session-id rule.\n\n## Execution Flow\n\n- Before each inspection, the CLI verifies SysOM activation and permissions (`InitialSysom`,\n  `source=skill_hub`); activation and installation prompts are handled by the CLI itself.\n- Every new inspection calls ROA API `POST /api/v1/inspection/createInstanceInspection` with\n  `source=skill_hub`; selected items come from `--query` keyword/intent mapping, and a query\n  matching no items falls back to a full inspection.\n- Each mode runs a full closed loop: inspect (metrics + logs) -> automatic root-cause diagnosis\n  on detected anomalies -> LLM-summarized Chinese report.\n- Automatic root-cause diagnosis is triggered via `InvokeDiagnosis` (injecting\n  `__sysom_diagnosis_source=skill_hub` into `params`) and polled via `GetDiagnosisResult`\n  until `success` / `fail` / timeout.\n- Batch (`--scope-type batch --instances ...`) inspects every specified instance; region-wide\n  (`--scope-type all`) auto-discovers all ECS instances in the region (limit 5000). Both\n  automatically diagnose the Top-3 most severe anomalous instances and include copy-ready\n  deep-dive commands for the remaining ones in the report.\n- Report lookup uses ROA API `GET /api/v1/inspection/getInspectionReport`; the CLI polls until\n  the report succeeds or times out.\n- `--report-id <reportId>` skips task creation and directly fetches the existing report;\n  inspection results also emit this replay command in `next_steps` automatically.\n- Local threshold/event-rule configuration is not used; anomaly decisions come from the\n  server-side inspection report.\n\n## Error Handling\n\nWhen a CLI invocation fails, classify the failure by the error text (`Error: <Code>: ...`)\nand handle it as follows instead of blind retries:\n\n- **Permission (`Forbidden.RAM`)**: explain that `sysom:InitialSysom` /\n  `sysom:InvokeAgentCli` is missing and point the user to `references/ram-policies.md`\n  for the minimum policy; do not retry.\n- **Parameter (`InvalidParameter`, invalid argument)**: identify the offending argument\n  and guide the user to verify the instance id and region; do not attribute it to the\n  service.\n- **Throttling (`Throttling`)**: tell the user the request was rate-limited and advise\n  retrying later; do not retry automatically in a loop.\n- **Internal (`InternalError`)**: report the temporary service failure honestly and\n  suggest retrying later; do not attribute it to user input.\n- **Empty region (`no ECS instances found`)**: not an error. Report that the region has\n  no ECS instances and skip the inspection; never fabricate a report.\n\n## Extensibility Notes\n\n- Inspection focus is controlled by `--query` (keyword/intent mapping to concrete items);\n  unmatched queries fall back to a full inspection.\n- Use `--scope-type batch --instances ...` for batch inspection and `--scope-type all` for the\n  whole region (limit 5000 instances); both auto-diagnose the Top-3 most severe anomalies.\n- Use `--report-id` to re-check an existing report without re-execution; the replay command is\n  emitted automatically in inspection `next_steps`.\n- A local Python CLI (`./scripts/osops.sh inspection`) is kept only as a fallback for\n  environments where `sysom-osops` is unavailable.\n- Memory anomaly trigger logic of the fallback path stays implemented in\n  `scripts/sysom_cli/inspection/command.py`.\n- To add more post-inspection specialized diagnosis actions, reuse the `InvokeDiagnosis`\n  integration pattern.\n\nFile v0.0.4:_meta.json\n\n{\n  \"ownerId\": \"kn74p5w8ywv6prh40g0s82gmqh83nw54\",\n  \"slug\": \"alibabacloud-alinux-sysom-inspection\",\n  \"version\": \"0.0.4\",\n  \"publishedAt\": 1787208693370\n}\n\nFile v0.0.4:references/ram-policies.md\n\n# RAM Policies: alibabacloud-alinux-sysom-inspection\n\nThis Skill uses the sysom-osops CLI. Remote diagnosis is routed through SysOM\nOpenAPI gateway actions.\n\n## Required Permissions\n\n| API | RAM Action | Used by | Description |\n|-----|------------|---------|-------------|\n| InitialSysom | `sysom:InitialSysom` | Credential validation inside remote commands | Verify credential validity and SysOM role authorization |\n| InvokeAgentCli | `sysom:InvokeAgentCli` | All remote diagnosis commands | Gateway action for catalog queries, diagnosis execution, and task polling |\n\n## Minimum Permission Policy\n\n```json\n{\n  \"Version\": \"1\",\n  \"Statement\": [\n    {\n      \"Effect\": \"Allow\",\n      \"Action\": [\n        \"sysom:InitialSysom\",\n        \"sysom:InvokeAgentCli\"\n      ],\n      \"Resource\": \"*\"\n    }\n  ]\n}\n```\n\n## Notes\n\n- `sysom-osops memory classify` runs locally and does not require cloud\n  permissions.\n- Remote commands across memory, IO, network, load, and Java memory require the\n  permissions above.\n- Avoid broader wildcard permissions when a custom least-privilege policy can be\n  attached to the RAM user or ECS RAM Role.\n- Do not paste AK/SK values into the conversation. Configure credentials outside\n  the Agent session.\n\nFile v0.0.4:references/report-template.md\n\n## Inspection Overview\n- Target Instance: `{instance_id}` ({region_id})\n- Inspection Time: `{report_time}`\n- Inspection Report: `{inspection_report_id}` (Status: {inspection_report_status})\n- Inspection Result: {inspection_report_result}\n- Report File: `{report_file_name}`\n- File Path: `{report_file_path}`\n\n## Abnormal Item Details\n{abnormal_items_markdown}\n\n## Diagnosis Information\n- Diagnosis Status: {diagnosis_status}\n- Diagnosis Task: `{diagnosis_task_id}`\n- Diagnosis Conclusion: {diagnosis_report_result}\n- Root Cause: {diagnosis_root_cause}\n- Suggestion: {diagnosis_suggestion}\n\n## Key Findings\n{diagnosis_key_findings}\n\n## Application Memory Usage Ranking (TOP10)\n{diagnosis_app_mem_ranking}\n\n## Final Conclusion\n{final_conclusion}\n\nFile v0.0.4:scripts/pyproject.toml\n\n[build-system]\nrequires = [\"setuptools>=45\", \"wheel\"]\nbuild-backend = \"setuptools.build_meta\"\n\n[project]\nname = \"sysom-inspection\"\nversion = \"0.1.0\"\ndescription = \"SysOM inspection CLI\"\nrequires-python = \">=3.10\"\ndependencies = [\n    \"requests==2.34.2\",\n    \"alibabacloud-tea-openapi==0.4.4\",\n    \"alibabacloud-tea-util==0.3.14\",\n]\n\n[project.scripts]\nsysom-inspection = \"sysom_cli.__main__:main\"\n\nFile v0.0.4:scripts/requirements.txt\n\nrequests==2.34.2\nalibabacloud-tea-openapi==0.4.4\nalibabacloud-tea-util==0.3.14\n\nFile v0.0.4:skill-card.md\n\n## Description:\n\nInspects ECS instance health, detects memory, disk, CPU, load, and resource-leak anomalies, and can trigger deep SysOM diagnosis for critical memory issues.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[sdk-team](https://clawhub.ai/user/sdk-team)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nCloud operations engineers and support teams use this skill to inspect Alibaba Cloud ECS instance health, identify resource anomalies, and produce diagnosis-oriented inspection reports for troubleshooting and routine risk checks.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The skill can direct users to install the SysOM CLI through a curl-to-sudo installer.\n\nMitigation: Use the installer only after trusting the upstream SysOM path and reviewing the command in the target environment.\n\nRisk: Inspection flows can activate SysOM and install a persistent agent on cloud instances.\n\nMitigation: Run with deliberately scoped regions and instance lists, confirm activation prompts intentionally, and treat agent installation as an infrastructure change.\n\nRisk: Alibaba Cloud credentials and generated reports may expose operational details.\n\nMitigation: Use least-privilege RAM permissions, avoid sharing AK/SK values in the agent session, and handle local report files as sensitive operational data.\n\n## Reference(s):\n\n- [RAM Policies](references/ram-policies.md)\n- [Inspection Report Template](references/report-template.md)\n\n## Skill Output:\n\n**Output Type(s):** [Text, Markdown, Shell commands, Configuration, Guidance]\n\n**Output Format:** [Markdown guidance with inline shell commands and optional JSON CLI output]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [May create local Markdown inspection reports under inspection-reports/ during fallback CLI execution.]\n\n## Skill Version(s):\n\n0.0.4 (source: ClawHub release metadata; artifact frontmatter version is 0.2.0)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.0.3: 16 files, 23236 bytes\n\nFiles: references/ram-policies.md (1630b), references/report-template.md (744b), scripts/init.sh (310b), scripts/osops.sh (618b), scripts/pyproject.toml (395b), scripts/requirements.txt (79b), scripts/sysom_cli/__init__.py (24b), scripts/sysom_cli/__main__.py (4409b), scripts/sysom_cli/inspection/__init__.py (24b), scripts/sysom_cli/inspection/command.py (53056b), scripts/sysom_cli/lib/__init__.py (24b), scripts/sysom_cli/lib/auth.py (3784b), scripts/sysom_cli/lib/openapi.py (7204b), skill-card.md (2389b), SKILL.md (4393b), _meta.json (155b)\n\nFile v0.0.3:SKILL.md\n\n---\nname: alibabacloud-alinux-sysom-inspection\nversion: 0.1.0\ndescription: >\n  Inspect ECS instance health, detect anomalies in memory, disk, CPU, load,\n  and resource leaks, and automatically trigger deep diagnosis when critical\n  memory issues are detected. Suitable for routine inspections, troubleshooting,\n  and risk warning scenarios. Trigger keywords: SysOM, inspection, instance\n  diagnosis, memory_usage_rate, memory usage.\nlayer: application\ncategory: os-ops\nlifecycle: operations\ntags:\n  - sysom\n  - inspection\n  - ecs\n  - memory\n  - diagnosis\nstatus: beta\n---\n\n# SysOM Inspection (`sysom-inspection`)\n\nRun `./scripts/osops.sh` from the skill root directory.\n\nCurrently implemented command:\n- `inspection`\n\n## Quick Start\n\n```bash\ncd <alibabacloud-alinux-sysom-inspection>\n./scripts/init.sh\n./scripts/osops.sh inspection \\\n  --region-id cn-hangzhou \\\n  --managed-type all\n```\n\n## Observability\n\n- **UA template (required for all SDK requests):**\n  - `AlibabaCloud-Agent-Skills/{SKILL_NAME}/{session-id}`\n  - Runtime resolved form in this skill: `AlibabaCloud-Agent-Skills/alibabacloud-alinux-sysom-inspection/<SKILL_SESSION_ID>`\n- **Unified session-id rule:**\n  - A single `SKILL_SESSION_ID` must be reused across all API calls in one CLI execution.\n  - Injection priority is: external env `SKILL_SESSION_ID` (preferred) -> auto-generated fallback `sid-<uuid4>`.\n  - Accepted format is `[A-Za-z0-9][A-Za-z0-9._:-]{7,127}`; invalid injected values fall back to generated id.\n  - The resolved value is exported to process env `SKILL_SESSION_ID` to keep downstream calls consistent.\n\n## Execution Flow\n\n- Before each inspection, the CLI calls ROA API `POST /api/v1/openapi/initial_sysom` (`source=skill_hub`) to verify permissions and SysOM activation.\n- If SysOM is not activated or role readiness is missing, the CLI interactively asks whether to continue with activation + installation.\n- After user confirmation, it calls `InitialSysom(check_only=false, source=skill_hub)` for activation, then calls `InstallAgentWithType`.\n- After installation, it re-checks readiness using `InitialSysom(check_only=true, source=skill_hub)`. Inspection continues only when re-check succeeds.\n- Local threshold/event-rule configuration is not used; anomaly decisions come from the server-side inspection report.\n- If `--instance-id` is not provided, the CLI calls `ListAllInstances` (`region` / `instanceType=ecs` / `managedType` / `current` / `pageSize`) and lets the user pick an instance interactively.\n- It always calls ROA inspection API `POST /api/v1/inspection/createInstanceInspection` with `source=skill_hub`, and supports optional `metricSource` (`cms` / `sysom` / `auto`).\n- If `--metric-source` is not explicitly provided, the CLI maps automatically from management status: `managed -> sysom`, `unmanaged -> cms`, `unknown -> auto`.\n- To inspect all items, pass `items=[]` (in CLI, provide an explicit empty `--inspection-items`).\n- If the standard inspection API returns `InvalidAction.NotFound`, the CLI marks the API as unavailable and stops follow-up flow to avoid invalid retries.\n- Report lookup uses ROA API `GET /api/v1/inspection/getInspectionReport`.\n- If create API is unavailable, the CLI still sends one `GetInspectionReport` probe call and records the result for observability.\n- If report contains `sysom:metric:memory_usage_rate` anomaly, the CLI automatically triggers `InvokeDiagnosis` for `memgraph`.\n- `InvokeDiagnosis` injects `__sysom_diagnosis_source=skill_hub` into `params` and validates business `code=Success`.\n- After diagnosis is started, the CLI polls `GetDiagnosisResult` until `success` / `fail` / timeout.\n- Auto diagnosis can be disabled via `--disable-memgraph-diagnosis`.\n\n## Extensibility Notes\n\n- Inspection items can be overridden via `--inspection-items`.\n- Instance filtering can be controlled by `--managed-type` (`managed` / `unmanaged` / `all`) and pagination args `--current`, `--page-size`.\n- Metric source can be specified via `--metric-source` (`cms` / `sysom` / `auto`); if omitted, default behavior is preserved.\n- If `InitialSysom` indicates not activated, the CLI asks for terminal confirmation before activation attempt + recheck.\n- Memory anomaly trigger logic is implemented in `scripts/sysom_cli/inspection/command.py`.\n- To add more post-inspection specialized diagnosis actions, reuse the `InvokeDiagnosis` integration pattern.\n\nFile v0.0.3:_meta.json\n\n{\n  \"ownerId\": \"kn74p5w8ywv6prh40g0s82gmqh83nw54\",\n  \"slug\": \"alibabacloud-alinux-sysom-inspection\",\n  \"version\": \"0.0.3\",\n  \"publishedAt\": 1783339547398\n}\n\nFile v0.0.3:references/ram-policies.md\n\n# RAM Policies (sysom-inspection)\n\nThis document describes the minimum RAM permissions required by `alibabacloud-alinux-sysom-inspection` when calling SysOM OpenAPI.\n\n## Required SysOM Actions\n\n| API | RAM Action | Purpose |\n|---|---|---|\n| `ListAllInstances` | `sysom:ListAllInstances` | List instances by region and management status (paginated) for inspection target selection |\n| `InitialSysom` | `sysom:InitialSysom` | Validate activation status and permissions; optionally perform activation |\n| `InstallAgentWithType` | `sysom:InstallAgentWithType` | Install SysOM Agent on the target ECS instance |\n| `CreateInstanceInspection` | `sysom:CreateInstanceInspection` | Start an instance inspection task |\n| `GetInspectionReport` | `sysom:GetInspectionReport` | Query inspection report details |\n| `InvokeDiagnosis` | `sysom:InvokeDiagnosis` | Start memory-focused diagnosis (`memgraph`) |\n| `GetDiagnosisResult` | `sysom:GetDiagnosisResult` | Poll diagnosis execution result |\n\n## Example Policy Statement\n\n```json\n{\n  \"Version\": \"1\",\n  \"Statement\": [\n    {\n      \"Effect\": \"Allow\",\n      \"Action\": [\n        \"sysom:ListAllInstances\",\n        \"sysom:InitialSysom\",\n        \"sysom:InstallAgentWithType\",\n        \"sysom:CreateInstanceInspection\",\n        \"sysom:GetInspectionReport\",\n        \"sysom:InvokeDiagnosis\",\n        \"sysom:GetDiagnosisResult\"\n      ],\n      \"Resource\": \"*\"\n    }\n  ]\n}\n```\n\n## Notes\n\n- If you use a RAM sub-account for inspection/diagnosis, ensure it has all actions listed above.\n- If the API indicates service is not activated or role readiness is missing, complete SysOM activation first and retry.\n\nFile v0.0.3:references/report-template.md\n\n## Inspection Overview\n- Target Instance: `{instance_id}` ({region_id})\n- Inspection Time: `{report_time}`\n- Inspection Report: `{inspection_report_id}` (Status: {inspection_report_status})\n- Inspection Result: {inspection_report_result}\n- Report File: `{report_file_name}`\n- File Path: `{report_file_path}`\n\n## Abnormal Item Details\n{abnormal_items_markdown}\n\n## Diagnosis Information\n- Diagnosis Status: {diagnosis_status}\n- Diagnosis Task: `{diagnosis_task_id}`\n- Diagnosis Conclusion: {diagnosis_report_result}\n- Root Cause: {diagnosis_root_cause}\n- Suggestion: {diagnosis_suggestion}\n\n## Key Findings\n{diagnosis_key_findings}\n\n## Application Memory Usage Ranking (TOP10)\n{diagnosis_app_mem_ranking}\n\n## Final Conclusion\n{final_conclusion}\n\nFile v0.0.3:scripts/pyproject.toml\n\n[build-system]\nrequires = [\"setuptools>=45\", \"wheel\"]\nbuild-backend = \"setuptools.build_meta\"\n\n[project]\nname = \"sysom-inspection\"\nversion = \"0.1.0\"\ndescription = \"SysOM inspection CLI\"\nrequires-python = \">=3.8\"\ndependencies = [\n    \"requests==2.34.2\",\n    \"alibabacloud-tea-openapi==0.4.4\",\n    \"alibabacloud-tea-util==0.3.14\",\n]\n\n[project.scripts]\nsysom-inspection = \"sysom_cli.__main__:main\"\n\nFile v0.0.3:scripts/requirements.txt\n\nrequests==2.34.2\nalibabacloud-tea-openapi==0.4.4\nalibabacloud-tea-util==0.3.14\n\nFile v0.0.3:skill-card.md\n\n## Description: <br>\nInspect ECS instance health, detect anomalies in memory, disk, CPU, load, and resource leaks, and trigger memory-focused diagnosis when critical memory issues are detected. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[sdk-team](https://clawhub.ai/user/sdk-team) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and cloud operations engineers use this skill to run Alibaba Cloud SysOM inspections on ECS instances, review anomalies, and optionally trigger memory diagnosis for troubleshooting and risk warning. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The skill can use Alibaba Cloud credentials for SysOM operations including activation, agent installation, inspection, and diagnosis. <br>\nMitigation: Use a least-privilege RAM policy, review interactive prompts, and run only for intended ECS instances. <br>\nRisk: Broad instance listing can expose more infrastructure scope than needed. <br>\nMitigation: Pass --instance-id when possible and limit RAM permissions to the required SysOM actions. <br>\nRisk: Automatic memory diagnosis may start follow-up diagnosis after a memory anomaly is detected. <br>\nMitigation: Use --disable-memgraph-diagnosis when automatic diagnosis is not desired. <br>\n\n\n## Reference(s): <br>\n- [RAM Policies](references/ram-policies.md) <br>\n- [Inspection Report Template](references/report-template.md) <br>\n- [ClawHub Skill Page](https://clawhub.ai/sdk-team/skills/alibabacloud-alinux-sysom-inspection) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [text, markdown, json, shell commands, configuration, guidance] <br>\n**Output Format:** [Terminal text, optional JSON, and Markdown inspection reports] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [May write inspection reports under inspection-reports/ and can prompt before SysOM activation or agent installation.] <br>\n\n## Skill Version(s): <br>\n0.0.3 (source: server release metadata; artifact frontmatter and pyproject.toml show 0.1.0) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v0.0.2: 15 files, 19852 bytes\n\nFiles: references/ram-policies.md (1630b), scripts/init.sh (310b), scripts/osops.sh (618b), scripts/pyproject.toml (395b), scripts/requirements.txt (79b), scripts/sysom_cli/__init__.py (24b), scripts/sysom_cli/__main__.py (3424b), scripts/sysom_cli/inspection/__init__.py (24b), scripts/sysom_cli/inspection/command.py (36181b), scripts/sysom_cli/lib/__init__.py (24b), scripts/sysom_cli/lib/auth.py (3776b), scripts/sysom_cli/lib/openapi.py (7152b), skill-card.md (2256b), SKILL.md (4381b), _meta.json (155b)\n\nFile v0.0.2:SKILL.md\n\n---\nname: alibabacloud-alinux-sysom-inspection\nversion: 0.1.0\ndescription: Inspect ECS instance health, detect anomalies in memory, disk, CPU, load, and resource leaks, and automatically trigger deep diagnosis when critical memory issues are detected. Suitable for routine inspections, troubleshooting, and risk warning scenarios. Trigger keywords: SysOM, inspection, instance diagnosis, memory_usage_rate, memory usage.\nlayer: application\ncategory: os-ops\nlifecycle: operations\ntags:\n  - sysom\n  - inspection\n  - ecs\n  - memory\n  - diagnosis\nstatus: beta\n---\n\n# SysOM Inspection (`sysom-inspection`)\n\nRun `./scripts/osops.sh` from the skill root directory.\n\nCurrently implemented command:\n- `inspection`\n\n## Quick Start\n\n```bash\ncd <alibabacloud-alinux-sysom-inspection>\n./scripts/init.sh\n./scripts/osops.sh inspection \\\n  --region-id cn-hangzhou \\\n  --managed-type all\n```\n\n## Observability\n\n- **UA template (required for all SDK requests):**\n  - `AlibabaCloud-Agent-Skills/{SKILL_NAME}/{session-id}`\n  - Runtime resolved form in this skill: `AlibabaCloud-Agent-Skills/alibabacloud-alinux-sysom-inspection/<SKILL_SESSION_ID>`\n- **Unified session-id rule:**\n  - A single `SKILL_SESSION_ID` must be reused across all API calls in one CLI execution.\n  - Injection priority is: external env `SKILL_SESSION_ID` (preferred) -> auto-generated fallback `sid-<uuid4>`.\n  - Accepted format is `[A-Za-z0-9][A-Za-z0-9._:-]{7,127}`; invalid injected values fall back to generated id.\n  - The resolved value is exported to process env `SKILL_SESSION_ID` to keep downstream calls consistent.\n\n## Execution Flow\n\n- Before each inspection, the CLI calls ROA API `POST /api/v1/openapi/initial_sysom` (`source=skill_hub`) to verify permissions and SysOM activation.\n- If SysOM is not activated or role readiness is missing, the CLI interactively asks whether to continue with activation + installation.\n- After user confirmation, it calls `InitialSysom(check_only=false, source=skill_hub)` for activation, then calls `InstallAgentWithType`.\n- After installation, it re-checks readiness using `InitialSysom(check_only=true, source=skill_hub)`. Inspection continues only when re-check succeeds.\n- Local threshold/event-rule configuration is not used; anomaly decisions come from the server-side inspection report.\n- If `--instance-id` is not provided, the CLI calls `ListAllInstances` (`region` / `instanceType=ecs` / `managedType` / `current` / `pageSize`) and lets the user pick an instance interactively.\n- It always calls ROA inspection API `POST /api/v1/inspection/createInstanceInspection` with `source=skill_hub`, and supports optional `metricSource` (`cms` / `sysom` / `auto`).\n- If `--metric-source` is not explicitly provided, the CLI maps automatically from management status: `managed -> sysom`, `unmanaged -> cms`, `unknown -> auto`.\n- To inspect all items, pass `items=[]` (in CLI, provide an explicit empty `--inspection-items`).\n- If the standard inspection API returns `InvalidAction.NotFound`, the CLI marks the API as unavailable and stops follow-up flow to avoid invalid retries.\n- Report lookup uses ROA API `GET /api/v1/inspection/getInspectionReport`.\n- If create API is unavailable, the CLI still sends one `GetInspectionReport` probe call and records the result for observability.\n- If report contains `sysom:metric:memory_usage_rate` anomaly, the CLI automatically triggers `InvokeDiagnosis` for `memgraph`.\n- `InvokeDiagnosis` injects `__sysom_diagnosis_source=skill_hub` into `params` and validates business `code=Success`.\n- After diagnosis is started, the CLI polls `GetDiagnosisResult` until `success` / `fail` / timeout.\n- Auto diagnosis can be disabled via `--disable-memgraph-diagnosis`.\n\n## Extensibility Notes\n\n- Inspection items can be overridden via `--inspection-items`.\n- Instance filtering can be controlled by `--managed-type` (`managed` / `unmanaged` / `all`) and pagination args `--current`, `--page-size`.\n- Metric source can be specified via `--metric-source` (`cms` / `sysom` / `auto`); if omitted, default behavior is preserved.\n- If `InitialSysom` indicates not activated, the CLI asks for terminal confirmation before activation attempt + recheck.\n- Memory anomaly trigger logic is implemented in `scripts/sysom_cli/inspection/command.py`.\n- To add more post-inspection specialized diagnosis actions, reuse the `InvokeDiagnosis` integration pattern.\n\nFile v0.0.2:_meta.json\n\n{\n  \"ownerId\": \"kn74p5w8ywv6prh40g0s82gmqh83nw54\",\n  \"slug\": \"alibabacloud-alinux-sysom-inspection\",\n  \"version\": \"0.0.2\",\n  \"publishedAt\": 1781714726236\n}\n\nFile v0.0.2:references/ram-policies.md\n\n# RAM Policies (sysom-inspection)\n\nThis document describes the minimum RAM permissions required by `alibabacloud-alinux-sysom-inspection` when calling SysOM OpenAPI.\n\n## Required SysOM Actions\n\n| API | RAM Action | Purpose |\n|---|---|---|\n| `ListAllInstances` | `sysom:ListAllInstances` | List instances by region and management status (paginated) for inspection target selection |\n| `InitialSysom` | `sysom:InitialSysom` | Validate activation status and permissions; optionally perform activation |\n| `InstallAgentWithType` | `sysom:InstallAgentWithType` | Install SysOM Agent on the target ECS instance |\n| `CreateInstanceInspection` | `sysom:CreateInstanceInspection` | Start an instance inspection task |\n| `GetInspectionReport` | `sysom:GetInspectionReport` | Query inspection report details |\n| `InvokeDiagnosis` | `sysom:InvokeDiagnosis` | Start memory-focused diagnosis (`memgraph`) |\n| `GetDiagnosisResult` | `sysom:GetDiagnosisResult` | Poll diagnosis execution result |\n\n## Example Policy Statement\n\n```json\n{\n  \"Version\": \"1\",\n  \"Statement\": [\n    {\n      \"Effect\": \"Allow\",\n      \"Action\": [\n        \"sysom:ListAllInstances\",\n        \"sysom:InitialSysom\",\n        \"sysom:InstallAgentWithType\",\n        \"sysom:CreateInstanceInspection\",\n        \"sysom:GetInspectionReport\",\n        \"sysom:InvokeDiagnosis\",\n        \"sysom:GetDiagnosisResult\"\n      ],\n      \"Resource\": \"*\"\n    }\n  ]\n}\n```\n\n## Notes\n\n- If you use a RAM sub-account for inspection/diagnosis, ensure it has all actions listed above.\n- If the API indicates service is not activated or role readiness is missing, complete SysOM activation first and retry.\n\nFile v0.0.2:scripts/pyproject.toml\n\n[build-system]\nrequires = [\"setuptools>=45\", \"wheel\"]\nbuild-backend = \"setuptools.build_meta\"\n\n[project]\nname = \"sysom-inspection\"\nversion = \"0.1.0\"\ndescription = \"SysOM inspection CLI\"\nrequires-python = \">=3.8\"\ndependencies = [\n    \"requests==2.34.2\",\n    \"alibabacloud-tea-openapi==0.4.4\",\n    \"alibabacloud-tea-util==0.3.14\",\n]\n\n[project.scripts]\nsysom-inspection = \"sysom_cli.__main__:main\"\n\nFile v0.0.2:scripts/requirements.txt\n\nrequests==2.34.2\nalibabacloud-tea-openapi==0.4.4\nalibabacloud-tea-util==0.3.14\n\nFile v0.0.2:skill-card.md\n\n## Description: <br>\nInspect ECS instance health, detect anomalies in memory, disk, CPU, load, and resource leaks, and automatically trigger deep diagnosis when critical memory issues are detected. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[sdk-team](https://clawhub.ai/user/sdk-team) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and operations engineers use this skill to inspect Alibaba Cloud ECS instance health, choose or target instances, review SysOM inspection reports, and trigger memory-focused diagnosis when reports identify critical memory usage anomalies. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The skill uses Alibaba Cloud credentials to inspect ECS instances and call SysOM APIs. <br>\nMitigation: Install and run it only when SysOM inspection is intended, and use scoped Alibaba Cloud RAM credentials with the actions documented in references/ram-policies.md. <br>\nRisk: SysOM activation and agent installation can change the target cloud environment. <br>\nMitigation: Review the activation prompt before confirming; in non-interactive runs, provide a ready SysOM environment and target instance so the skill does not need activation flow. <br>\nRisk: Memory anomalies can trigger automatic memgraph diagnosis. <br>\nMitigation: Use --disable-memgraph-diagnosis when automatic memory diagnosis is not desired. <br>\n\n\n## Reference(s): <br>\n- [RAM Policies](references/ram-policies.md) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [text, markdown, shell commands, configuration, guidance] <br>\n**Output Format:** [Markdown with inline shell commands and CLI result summaries] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [May return JSON-formatted inspection and diagnosis results when the CLI is run with --json.] <br>\n\n## Skill Version(s): <br>\n0.0.2 (source: server release metadata) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v0.0.1: 15 files, 17055 bytes\n\nFiles: references/ram-policies.md (1326b), scripts/init.sh (310b), scripts/osops.sh (618b), scripts/pyproject.toml (395b), scripts/requirements.txt (79b), scripts/sysom_cli/__init__.py (24b), scripts/sysom_cli/__main__.py (3294b), scripts/sysom_cli/inspection/__init__.py (24b), scripts/sysom_cli/inspection/command.py (25161b), scripts/sysom_cli/lib/__init__.py (24b), scripts/sysom_cli/lib/auth.py (3776b), scripts/sysom_cli/lib/openapi.py (6151b), skill-card.md (2152b), SKILL.md (2862b), _meta.json (155b)\n\nFile v0.0.1:SKILL.md\n\n---\nname: alibabacloud-alinux-sysom-inspection\nversion: 0.1.0\ndescription: 用于检查 ECS 实例的系统健康状况，识别内存、磁盘、CPU、负载与资源泄漏等异常，并在命中关键内存问题时自动补充深度诊断结果。适用于实例巡检、故障排查与风险预警场景。触发词：SysOM、巡检、实例诊断、memory_usage_rate、内存使用率。\nlayer: application\ncategory: os-ops\nlifecycle: operations\ntags:\n  - sysom\n  - inspection\n  - ecs\n  - memory\n  - diagnosis\nstatus: beta\n---\n\n# SysOM 巡检（sysom-inspection）\n\n在技能根目录执行 `./scripts/osops.sh`。\n\n当前实现命令：\n- `inspection`\n\n## 快速开始\n\n```bash\ncd <alibabacloud-alinux-sysom-inspection>\n./scripts/init.sh\n./scripts/osops.sh inspection \\\n  --region-id cn-hangzhou \\\n  --instance-id i-xxx\n```\n\n## 执行逻辑\n\n- 每次执行巡检前先调用 ROA 接口 `POST /api/v1/openapi/initial_sysom`（`source=skill_hub`），用于判断用户是否具备权限且 SysOM 已开通。\n- 若未开通或角色未就绪，命令会交互式询问是否继续“开通+安装 SysOM”。\n- 用户同意后先调用 `InitialSysom(check_only=false, source=skill_hub)` 执行开通，再调用 `InstallAgentWithType` 安装。\n- 安装后会再次调用 `InitialSysom(check_only=true, source=skill_hub)` 复检，复检通过才继续巡检与诊断。\n- 不再本地配置阈值/事件规则，异常判断由服务端巡检报告决定。\n- 固定调用 ROA 巡检接口：`POST /api/v1/inspection/createInstanceInspection`，并固定传 `source=skill_hub`。\n- 若需要巡检全部项目，可传 `items=[]`（CLI 中为显式传空 `--inspection-items`）。\n- 若标准巡检 API 返回 `InvalidAction.NotFound`，CLI 会标记“当前版本不可用”并停止后续流程，避免无效重试。\n- 报告查询调用 ROA 接口：`GET /api/v1/inspection/getInspectionReport`。\n- 当创建接口不可用时，CLI 会补发一次 `GetInspectionReport` 探测调用并记录结果，确保日志中可观测到该动作。\n- 巡检报告中若命中 `sysom:metric:memory_usage_rate` 异常，自动调用 `InvokeDiagnosis` 发起 `memgraph` 诊断。\n- `InvokeDiagnosis` 的 `params` 会注入 `__sysom_diagnosis_source=skill_hub`，并校验业务 `code=Success`。\n- 发起诊断后自动轮询 `GetDiagnosisResult`，直到 `success` / `fail` / 超时。\n- 可通过 `--disable-memgraph-diagnosis` 关闭自动诊断。\n\n## 可扩展性约定\n\n- 巡检项可通过 `--inspection-items` 传入覆盖默认列表。\n- 若 InitialSysom 返回未开通，CLI 会在终端进行交互式确认后再执行开通尝试+重检。\n- 内存异常触发诊断的判定逻辑位于 `scripts/sysom_cli/inspection/command.py`。\n- 如需新增“巡检命中后触发的专项诊断”，可复用 `InvokeDiagnosis` 调用方式扩展。\n\nFile v0.0.1:_meta.json\n\n{\n  \"ownerId\": \"kn74p5w8ywv6prh40g0s82gmqh83nw54\",\n  \"slug\": \"alibabacloud-alinux-sysom-inspection\",\n  \"version\": \"0.0.1\",\n  \"publishedAt\": 1779270946062\n}\n\nFile v0.0.1:references/ram-policies.md\n\n# RAM Policies (sysom-inspection)\n\n本文档说明 `alibabacloud-alinux-sysom-inspection` 在调用 SysOM OpenAPI 时所需的最小 RAM 权限。\n\n## Required SysOM Actions\n\n| API | RAM Action | Purpose |\n|---|---|---|\n| `InitialSysom` | `sysom:InitialSysom` | 校验开通状态与权限，必要时执行开通流程 |\n| `InstallAgentWithType` | `sysom:InstallAgentWithType` | 为目标 ECS 安装 SysOM Agent |\n| `CreateInstanceInspection` | `sysom:CreateInstanceInspection` | 发起实例巡检任务 |\n| `GetInspectionReport` | `sysom:GetInspectionReport` | 查询巡检报告 |\n| `InvokeDiagnosis` | `sysom:InvokeDiagnosis` | 发起内存专项诊断（memgraph） |\n| `GetDiagnosisResult` | `sysom:GetDiagnosisResult` | 轮询诊断结果 |\n\n## Example Policy Statement\n\n```json\n{\n  \"Version\": \"1\",\n  \"Statement\": [\n    {\n      \"Effect\": \"Allow\",\n      \"Action\": [\n        \"sysom:InitialSysom\",\n        \"sysom:InstallAgentWithType\",\n        \"sysom:CreateInstanceInspection\",\n        \"sysom:GetInspectionReport\",\n        \"sysom:InvokeDiagnosis\",\n        \"sysom:GetDiagnosisResult\"\n      ],\n      \"Resource\": \"*\"\n    }\n  ]\n}\n```\n\n## Notes\n\n- 若使用子账号执行巡检/诊断，需确保该账号具备以上全部 Action。\n- 若提示服务未开通或角色未就绪，请先完成 SysOM 开通流程后重试。\n\nFile v0.0.1:scripts/pyproject.toml\n\n[build-system]\nrequires = [\"setuptools>=45\", \"wheel\"]\nbuild-backend = \"setuptools.build_meta\"\n\n[project]\nname = \"sysom-inspection\"\nversion = \"0.1.0\"\ndescription = \"SysOM inspection CLI\"\nrequires-python = \">=3.8\"\ndependencies = [\n    \"requests==2.34.2\",\n    \"alibabacloud-tea-openapi==0.4.4\",\n    \"alibabacloud-tea-util==0.3.14\",\n]\n\n[project.scripts]\nsysom-inspection = \"sysom_cli.__main__:main\"\n\nFile v0.0.1:scripts/requirements.txt\n\nrequests==2.34.2\nalibabacloud-tea-openapi==0.4.4\nalibabacloud-tea-util==0.3.14\n\nFile v0.0.1:skill-card.md\n\n## Description: <br>\nChecks Alibaba Cloud ECS instance health with SysOM, covering memory, disk, CPU, load, and resource-leak issues, and can add memgraph diagnostics when memory usage anomalies are reported. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[sdk-team](https://clawhub.ai/user/sdk-team) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nCloud operations engineers use this skill to run SysOM inspections on Alibaba Cloud ECS instances, retrieve inspection reports, and investigate memory-pressure findings with optional memgraph diagnosis. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The tool can enable SysOM and install the SysOM agent on a target ECS instance after interactive confirmation. <br>\nMitigation: Use a least-privilege RAM policy, verify the target region and instance ID, and approve activation or installation only when intended. <br>\nRisk: The tool calls Alibaba Cloud SysOM APIs with user-provided or instance-resolved cloud credentials. <br>\nMitigation: Run it with credentials limited to the required SysOM actions and protect environment, profile, and ECS RAM role credential sources. <br>\n\n\n## Reference(s): <br>\n- [RAM Policies](references/ram-policies.md) <br>\n- [ClawHub skill page](https://clawhub.ai/sdk-team/alibabacloud-alinux-sysom-inspection) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [Shell commands, Text, JSON, Guidance] <br>\n**Output Format:** [Terminal text or JSON from the SysOM inspection CLI] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [May return nonzero exit codes for authentication failure, unavailable inspection APIs, or detected memory issues.] <br>\n\n## Skill Version(s): <br>\n0.0.1 (source: server release evidence; artifact frontmatter reports 0.1.0) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>","readmeExcerpt":"Skill: alibabacloud-alinux-sysom-inspection Owner: sdk-team Summary: Inspect ECS instance health, detect anomalies in memory, disk, CPU, load, and resource leaks, and automatically trigger deep diagnosis when critical memory issues are detected. Suitable for routine inspections, troubleshooting, and risk warning scenarios. Trigger keywords: SysOM, inspection, instance diagnosis, memory_usage_rate, memory usage. Tags:","codeSnippets":[],"executableExamples":[{"language":"bash","snippet":"command -v sysom-osops"},{"language":"bash","snippet":"curl -fsSL --connect-timeout 1000 https://sysom-prd-cn-hangzhou.oss-cn-hangzhou.aliyuncs.com/sysom_prd/skill_cli/install.sh | sudo bash"},{"language":"bash","snippet":"curl -fsSL --connect-timeout 1000 https://sysom-prd-cn-hangzhou.oss-cn-hangzhou.aliyuncs.com/sysom_prd/skill_cli/install.sh | sudo bash"},{"language":"bash","snippet":"command -v sysom-osops"},{"language":"bash","snippet":"# Focused inspection by intent (--query)\n# Run only CPU/load related items (keyword mapping)\nsysom-osops inspection ecs --region cn-shenzhen --instance i-xxxxxxxx --query \"cpu related inspection\"\n\n# Combined intent: memory and disk\nsysom-osops inspection ecs --region cn-shenzhen --instance i-xxxxxxxx --query \"memory and disk\"\n\n# Natural-language sentence: intent is extracted automatically, matching packet-loss items\nsysom-osops inspection ecs --region cn-shenzhen --instance i-xxxxxxxx --query \"check whether this machine has network packet loss\"\n\n# If the query matches no items, it falls back to a full inspection automatically\n\n# Batch inspection (--scope-type batch, auto diagnosis supported)\n# Inspect all specified instances -> auto root-cause diagnosis on the Top-3 most severe\n# anomalous instances -> LLM summary (the rest get copy-ready deep-dive commands in the report)\nsysom-osops inspection ecs --region cn-shenzhen --scope-type batch --instances i-aaa,i-bbb,i-ccc\n\n# Region-wide inspection (--scope-type all, auto diagnosis supported)\n# Auto-discover every ECS instance in the region (limit 5000) -> Top-3 anomalies auto-diagnosed\n# -> LLM summary; one command for the full closed loop\nsysom-osops inspection ecs --region cn-shenzhen --scope-type all\n\n# Re-check an existing report (--report-id)\n# Returns immediately without re-running (auto-generated in inspection next_steps).\n# IMPORTANT: --region and --scope-type (or --instance) MUST match the original\n# inspection command, otherwise the replay will fail with MissingParam errors.\nsysom-osops inspection ecs --region cn-shenzhen --scope-type all --report-id inspection-82a64d9d-11c5-45b2-a81c-27fc754891e8"},{"language":"json","snippet":"{\n  \"Version\": \"1\",\n  \"Statement\": [\n    {\n      \"Effect\": \"Allow\",\n      \"Action\": [\n        \"sysom:InitialSysom\",\n        \"sysom:InvokeAgentCli\"\n      ],\n      \"Resource\": \"*\"\n    },\n    {\n      \"Effect\": \"Allow\",\n      \"Action\": \"ram:CreateServiceLinkedRole\",\n      \"Resource\": \"*\",\n      \"Condition\": {\n        \"StringEquals\": {\n          \"ram:ServiceName\": \"sysom.aliyuncs.com\"\n        }\n      }\n    }\n  ]\n}"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: alibabacloud-alinux-sysom-inspection\nversion: 0.2.0\ndescription: >\n  Inspect ECS instance health, detect anomalies in memory, disk, CPU, load,\n  and resource leaks, and automatically trigger deep diagnosis when critical\n  memory issues are detected. Suitable for routine inspections, troubleshooting,\n  and risk warning scenarios. Trigger keywords: SysOM, inspection, instance\n  diagnosis, memory_usage_rate, memory usage.\nlayer: application\ncategory: os-ops\nlifecycle: operations\ntags:\n  - sysom\n  - inspection\n  - ecs\n  - memory\n  - diagnosis\nstatus: beta\n---\n\n# SysOM Inspection (`sysom-inspection`)\n\nInspections are launched with the `sysom-osops` CLI command\n(`sysom-osops inspection ecs ...`). Always go through the CLI instead of calling\nthe inspection OpenAPI directly.\n\n## CLI Setup\n\nCheck whether the CLI is available:\n\n```bash\ncommand -v sysom-osops\n```\n\nIf it is missing, install it:\n\n```bash\ncurl -fsSL --connect-timeout 1000 https://sysom-prd-cn-hangzhou.oss-cn-hangzhou.aliyuncs.com/sysom_prd/skill_cli/install.sh | sudo bash\n```\n\nThen verify only the binary:\n\n```bash\ncommand -v sysom-osops\n```\n\nIf the CLI is installed but has no `inspection` subcommand yet, run\n`sysom-osops update` first, then retry.\n\nIf a command fails due to missing RAM permissions, follow\n`references/ram-policies.md` to attach the minimum permission policy.\n\n## Quick Start\n\n```bash\n# Focused inspection by intent (--query)\n# Run only CPU/load related items (keyword mapping)\nsysom-osops inspection ecs --region cn-shenzhen --instance i-xxxxxxxx --query \"cpu related inspection\"\n\n# Combined intent: memory and disk\nsysom-osops inspection ecs --region cn-shenzhen --instance i-xxxxxxxx --query \"memory and disk\"\n\n# Natural-language sentence: intent is extracted automatically, matching packet-loss items\nsysom-osops inspection ecs --region cn-shenzhen --instance i-xxxxxxxx --query \"check whether this machine has network packet loss\"\n\n# If the query matches no items, it falls back to a full inspection automatically\n\n# Batch inspection (--scope-type batch, auto diagnosis supported)\n# Inspect all specified instances -> auto root-cause diagnosis on the Top-3 most severe\n# anomalous instances -> LLM summary (the rest get copy-ready deep-dive commands in the report)\nsysom-osops inspection ecs --region cn-shenzhen --scope-type batch --instances i-aaa,i-bbb,i-ccc\n\n# Region-wide inspection (--scope-type all, auto diagnosis supported)\n# Auto-discover every ECS instance in the region (limit 5000) -> Top-3 anomalies auto-diagnosed\n# -> LLM summary; one command for the full closed loop\nsysom-osops inspection ecs --region cn-shenzhen --scope-type all\n\n# Re-check an existing report (--report-id)\n# Returns immediately without re-running (auto-generated in inspection next_steps).\n# IMPORTANT: --region and --scope-type (or --instance) MUST match the original\n# inspection command, otherwise the replay will fail with MissingParam errors.\nsysom-osops inspection ecs --region cn-shenzhen --scope-type"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn74p5w8ywv6prh40g0s82gmqh83nw54\",\n  \"slug\": \"alibabacloud-alinux-sysom-inspection\",\n  \"version\": \"0.0.5\",\n  \"publishedAt\": 1788839375123\n}"},{"path":"references/manifest.json","content":"{\"version\":\"0.0.5\"}"},{"path":"references/ram-policies.md","content":"# RAM Policies: alibabacloud-alinux-sysom-inspection\n\nThis Skill uses the sysom-osops CLI. Remote diagnosis is routed through SysOM\nOpenAPI gateway actions.\n\n## Required Permissions\n\n| API | RAM Action | Used by | Description |\n|-----|------------|---------|-------------|\n| InitialSysom | `sysom:InitialSysom` | Credential validation inside remote commands | Verify credential validity and SysOM role authorization |\n| InvokeAgentCli | `sysom:InvokeAgentCli` | All remote diagnosis commands | Gateway action for catalog queries, diagnosis execution, and task polling |\n| CreateServiceLinkedRole | `ram:CreateServiceLinkedRole` | First-time SysOM service activation | Create the SysOM service-linked role (SLR). Only needed on first activation. |\n\n## Minimum Permission Policy\n\n```json\n{\n  \"Version\": \"1\",\n  \"Statement\": [\n    {\n      \"Effect\": \"Allow\",\n      \"Action\": [\n        \"sysom:InitialSysom\",\n        \"sysom:InvokeAgentCli\"\n      ],\n      \"Resource\": \"*\"\n    },\n    {\n      \"Effect\": \"Allow\",\n      \"Action\": \"ram:CreateServiceLinkedRole\",\n      \"Resource\": \"*\",\n      \"Condition\": {\n        \"StringEquals\": {\n          \"ram:ServiceName\": \"sysom.aliyuncs.com\"\n        }\n      }\n    }\n  ]\n}\n```\n\n## Notes\n\n- `sysom-osops memory classify` runs locally and does not require cloud\n  permissions.\n- Remote commands across memory, IO, network, load, and Java memory require the\n  permissions above.\n- `ram:CreateServiceLinkedRole` is only required when activating SysOM for the\n  first time. Once the service-linked role exists, subsequent calls succeed\n  without this permission.\n- Avoid broader wildcard permissions when a custom least-privilege policy can be\n  attached to the RAM user or ECS RAM Role.\n- Do not paste AK/SK values into the conversation. Configure credentials outside\n  the Agent session."},{"path":"references/report-template.md","content":"## Inspection Overview\n- Target Instance: `{instance_id}` ({region_id})\n- Inspection Time: `{report_time}`\n- Inspection Report: `{inspection_report_id}` (Status: {inspection_report_status})\n- Inspection Result: {inspection_report_result}\n- Report File: `{report_file_name}`\n- File Path: `{report_file_path}`\n\n## Abnormal Item Details\n{abnormal_items_markdown}\n\n## Diagnosis Information\n- Diagnosis Status: {diagnosis_status}\n- Diagnosis Task: `{diagnosis_task_id}`\n- Diagnosis Conclusion: {diagnosis_report_result}\n- Root Cause: {diagnosis_root_cause}\n- Suggestion: {diagnosis_suggestion}\n\n## Key Findings\n{diagnosis_key_findings}\n\n## Application Memory Usage Ranking (TOP10)\n{diagnosis_app_mem_ranking}\n\n## Final Conclusion\n{final_conclusion}"}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":"Inspect ECS instance health, detect anomalies in memory, disk, CPU, load, and resource leaks, and automatically trigger deep diagnosis when critical memory issues are detected. Suitable for routine inspections, troubleshooting, and risk warning scenarios. Trigger keywords: SysOM, inspection, instance diagnosis, memory_usage_rate, memory usage. Skill: alibabacloud-alinux-sysom-inspection Owner: sdk-team Summary: Inspect ECS instance health, detect anomalies in memory, disk, CPU, load, and resource leaks, and automatically trigger deep diagnosis when critical memory issues are detected. Suitable for routine inspections, troubleshooting, and risk warning scenarios. Trigger keywords: SysOM, inspection, instance diagnosis, memory_usage_rate, memory usage. Tags:","editorialQuality":{"score":100,"threshold":65,"status":"ready","wordCount":1133,"uniquenessScore":49,"reasons":[]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-11T00:31:43.677Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-11T00:31:43.677Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-11T03:56:57.099Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}